Information Security & Data Protection Policy

The Marketing Department Ltd is committed to protecting the confidentiality, integrity and availability of the information entrusted to us by our clients, suppliers, employees and other stakeholders.

We recognise that information security is fundamental to maintaining trust and complying with our legal obligations under the UK GDPR and Data Protection Act 2018.

1. Collection and Use of Personal Information

We only collect personal information where there is a legitimate business purpose or where consent has been provided.

Information may be collected through:

  • Website enquiry forms

  • Newsletter subscriptions

  • Client engagements

  • Business networking and direct communications

Where individuals subscribe to our newsletter, their contact details are securely stored within our approved marketing and CRM platforms. This information is used solely to communicate news, insights and updates from The Marketing Department. Every marketing email includes a simple unsubscribe mechanism, allowing recipients to withdraw consent at any time.

We never sell personal information or disclose it to third parties for marketing purposes.

2. Client Information

During the course of delivering projects we may be granted access to client systems or information including, but not limited to:

  • CRM platforms

  • Marketing platforms

  • Website administration systems

  • Analytics platforms

  • Limited business contact information

Examples include Salesforce, HubSpot, Mailchimp, Microsoft 365 and similar business systems.

Access is granted only to employees directly involved in the delivery of the project and only for the duration required.

Where client data must be exported to complete agreed work (for example CRM cleansing, migration or consolidation projects), copies are retained only for as long as necessary to complete the work and are securely deleted once the project has concluded or the data has been returned to the client.

3. Information Security

The Marketing Department operates a cloud-first approach using established enterprise technology providers.

Our security measures include:

  • Password-protected systems

  • Multi-factor authentication wherever supported

  • Encrypted transmission of data using TLS/HTTPS

  • Encryption provided by our cloud service providers for data stored at rest

  • Role-based access to business systems

  • Secure cloud backup of business data

  • Regular operating system and software updates

  • Antivirus and endpoint protection on company devices

Access to business systems is granted only where required for an individual's role.

4. Data Storage

Business information is stored using trusted cloud providers with appropriate technical and organisational security measures.

Where available, we select UK or European data residency options for client information.

Information is retained only for as long as required to deliver our services, comply with legal obligations or satisfy contractual requirements.

5. Confidentiality

All employees are expected to maintain the confidentiality of client information both during and after their employment.

Confidential information is never disclosed to third parties unless:

  • authorised by the client;

  • required by law; or

  • necessary to deliver agreed services through approved suppliers.

6. CCTV

Our Glasgow office is located within Alexander Stephen House, operated by Govan Workspace.

Building security, including CCTV, is managed by the building operator. The Marketing Department does not control or have access to CCTV recordings. Any requests relating to CCTV footage should be directed to the building management.

7. Data Subject Rights

Individuals have the right to:

  • request access to their personal information;

  • request correction of inaccurate information;

  • request deletion where appropriate;

  • restrict or object to certain processing;

  • request portability where applicable.

Requests can be made by contacting:

Chris Graham
The Marketing Department Ltd
chris@themarketingdepartment.scot

8. Security Incidents

Any suspected loss, unauthorised disclosure or compromise of information is treated as a security incident.

Incidents are investigated promptly, appropriate corrective action is taken and, where required by law, affected clients and the Information Commissioner's Office are notified.

9. Policy Review

This policy is reviewed periodically and updated whenever significant changes occur to legislation, business operations or technology.